EDBT 2026 Demo / reviewers in the wild / expert
Benjamin Green 0001
dblp:116/5938-1
· DBLP profile ↗
7ranked-venue papers
1as first author
4since 2021 · last 2023
0000-0002-1013-9933ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Walking under the ladder logic: PLC-VBS: a PLC control logic vulnerability scanning toolabstractCyber security risk assessments provide a crucial starting point towards the understanding of existing risk exposure, via which suitable mitigation strategies can be formed. Risk is viewed as a product of threat, vulnerability and impact, and equal understanding of each of these elements is vitally important. This can be a challenge in Industrial Control System (ICS) environments, where adopted technologies are typically not only bespoke, but interact directly with the physical world. To date, existing vulnerability identification has focused on traditional vulnerability categories. While this approach provides risk assessors with a baseline understanding and the ability to hypothesize about potential resulting impacts, it is rather high level, operating at a level of abstraction that would be viewed as incomplete within a traditional information system context. The work presented in this paper takes the understanding of ICS device vulnerabilities a step deeper. It offers a tool, PLC-VBS, that helps identify Programmable Logic Controller (PLC) vulnerabilities, specifically within logic used to monitor, control, and automate operational processes. PLC-VBS gives risk assessors a more coherent picture about the potential impact should the identified vulnerabilities be exploited; this applies specifically to operational process elements. Sam Maesschalck, Alexander Staves, Richard Derbyshire, Benjamin Green 0001, David Hutchison 0001 |
Comput. Secur. | 4 |
| 2022 | Don't get stung, cover your ICS in honey: How do honeypots fit within industrial control system securityabstractThe advent of Industry 4.0 and smart manufacturing has led to an increased convergence of traditional manufacturing and production technologies with IP communications. Legacy Industrial Control System (ICS) devices, now interconnected via public networks, are exposed to a wide range of previously unconsidered threats, which must be considered to ensure the continued safe operation of industrial processes. This paper surveys the ICS honeypot deployments in the literature to date, provides an overview of ICS focused threat vectors, and studies how honeypots can be integrated within an organisations defensive strategy. We discuss relevant legislation, such as the UK Cyber Assessment Framework, the US NIST Framework for Improving Critical Infrastructure Cybersecurity, and associated industry-based standards and guidelines supporting operator compliance. This is used to frame a discussion on our survey of existing ICS honeypot implementations, and the role of honeypots in supporting regulatory objectives. We observe that many low-interaction honeypots are limited in their use. This is largely due to the increased knowledge attackers have on how real-world ICS devices are configured and operate vs the configurability of simulated honeypot systems. Furthermore, we find that environments with increased interaction provide more extensive capabilities and value, due to their inherent obfuscation delivered through the use of real-world systems. Based on these insights, we propose a novel framework towards the classification and implementation of ICS honeypots. Sam Maesschalck, Vasileios Giotsas, Benjamin Green 0001, Nicholas J. P. Race |
Comput. Secur. | 3 |
| 2021 | "Talking a different Language": Anticipating adversary attack cost for cyber risk assessmentabstractTypical cyber security risk assessment methods focus on the system under consideration, its vulnerabilities, and the resulting impact in the event of a system compromise. Cyber security, however, increasingly requires anticipating the moves of intelligent adversaries, who make decisions based on a range of factors including the cost of their attacks. A study of current risk assessment literature and industry practice shows that consideration of this cost is a notable gap in the understanding of adversaries. The factors of cost experienced by an adversary are established in this paper as Time, Finance, and Risk, supported by a practical study undertaken with relevant security practitioners. Using these factors as a base, a framework is proposed and developed to support the probabilistic determination of cost incurred by an adversary. This framework is an important extension to existing cyber security risk assessments, and is demonstrated in the paper through the use of a case study. Richard Derbyshire, Benjamin Green 0001, David Hutchison 0001 |
Comput. Secur. | 2 |
| 2021 | PCaaD: Towards automated determination and exploitation of industrial systemsabstractOver the last decade, Programmable Logic Controllers (PLCs) have been increasingly targeted by attackers to obtain control over industrial processes that support critical services.Such targeted attacks typically require detailed knowledge of system-specific attributes, including hardware configurations, adopted protocols, and PLC control-logic, i.e., process comprehension.The consensus from both academics and practitioners suggests stealthy process comprehension obtained from a PLC alone, to execute targeted attacks, is impractical.In contrast, we assert that current PLC programming practices open the door to a new vulnerability class, affording attackers an increased level of process comprehension.To support this, we propose the concept of Process Comprehension at a Distance (PCaaD), as a novel methodological and automatable approach towards the system-agnostic identification of PLC library functions.This leads to the targeted exfiltration of operational data, manipulation of control-logic behavior, and establishment of covert command and control channels through unused memory.We validate PCaaD on widely used PLCs through its practical application. Benjamin Green 0001, Richard Derbyshire, Marina Krotofil, William Knowles, Daniel Prince, Neeraj Suri |
Comput. Secur. | 1 |
| 2020 | Fast and Furious: Outrunning Windows Kernel Notification Routines from User-Mode
Pierre Ciholas, Jose M. Such, Angelos K. Marnerides, Benjamin Green 0001, Utz Roedig |
DIMVA | 4 |
| 2019 | Everything Is Awesome! or Is It? Cyber Security Risks in Critical Infrastructure
Awais Rashid, Joseph Gardiner, Benjamin Green 0001, Barnaby Craggs |
CRITIS | 3 |
| 2017 | Panning for gold: Automatically analysing online social engineering attack surfacesabstractThe process of social engineering targets people rather than IT infrastructure. Attackers use deceptive ploys to create compelling behavioural and cosmetic hooks, which in turn lead a target to disclose sensitive information or to interact with a malicious payload. The creation of such hooks requires background information on targets. Individuals are increasingly releasing information about themselves online, particularly on social networks. Though existing research has demonstrated the social engineering risks posed by such open source intelligence, this has been accomplished either through resource-intensive manual analysis or via interactive information harvesting techniques. As manual analysis of large-scale online information is impractical, and interactive methods risk alerting the target, alternatives are desirable. In this paper, we demonstrate that key information pertinent to social engineering attacks on organisations can be passively harvested on a large-scale in an automated fashion. We address two key problems. We demonstrate that it is possible to automatically identify employees of an organisation using only information which is visible to a remote attacker as a member of the public. Secondly, we show that, once identified, employee profiles can be linked across multiple online social networks to harvest additional information pertinent to successful social engineering attacks. We further demonstrate our approach through analysis of the social engineering attack surface of real critical infrastructure organisations. Based on our analysis we propose a set of countermeasures including an automated social engineering vulnerability scanner that organisations can use to analyse their exposure to potential social engineering attacks arising from open source intelligence. Matthew Edwards 0001, Robert Larson, Benjamin Green 0001, Awais Rashid, Alistair Baron |
Comput. Secur. | 3 |